Detect Wordfence

WordPress pluginsSecurity

Wordfence is a security plugin for sites that use WordPress. Wordfence includes an endpoint firewall and malware scanner.

Detection looks at script sources, javascript globals across 2 fingerprint rules among the site's public responses.

01

Websites using Wordfence

Loading website list…

02

Signal classes

PluginView evaluates public page signals in these classes when identifying Wordfence. Individual fingerprint rule bodies are proprietary and are not published.

  • Script sources
  • JavaScript globals
03

Example public indicators for Wordfence

Illustrative indicators derived from public catalog metadata for Wordfence. A live scan may match additional proprietary rules beyond these examples.

  • wp-content/plugins/wordfence/.admin.ajaxWatcher.0.js?ver=0.0?
  • wordfenceAJAXWatcher
04

What a detection means

Establishes
One or more public signals on the scanned page matched a known Wordfence signature (2 rules) at the time of the scan.
Does not establish
A sitewide install of Wordfence, an active vendor contract, exclusive use, or that Wordfence is still in place today.
05

How to check a site for Wordfence

  1. 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest Wordfence signals.
  2. 2. PluginView reads only public responses (script sources, javascript globals) and scores them against the Wordfence signature set (2 rules).
  3. 3. Review the confidence score and text explanation for Wordfence on the results page.
06

FAQ: detecting Wordfence

Can PluginView detect Wordfence without logging in?
Yes. PluginView only reads publicly accessible responses when checking for Wordfence — typically script sources, javascript globals. It does not bypass authentication or paywalls.
What category is Wordfence?
Wordfence is classified under WordPress plugins, Security in the PluginView directory.
How many fingerprint rules cover Wordfence?
This reference currently tracks 2 fingerprint rules across script sources, javascript globals. Individual rule bodies are proprietary and are not published.
What public signals suggest a site uses Wordfence?
Illustrative public indicators for Wordfence include wp-content/plugins/wordfence/.admin.ajaxWatcher.0.js?ver=0.0?; wordfenceAJAXWatcher. A live scan may match additional proprietary rules beyond these examples.

More in Security

View category →